ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืคึฟืึทืจ Java SE, MySQL, VirtualBox ืื•ืŸ ืื ื“ืขืจืข ืึธืจืึทืงืœืข ืคึผืจืึธื“ื•ืงื˜ืŸ ืžื™ื˜ ืคืึทืจืคืขืกื˜ื™ืงื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–

ืึธืจืึทืงืœืข ืคึฟื™ืจืžืข ืืจื•ื™ืก ืคึผืœืึทื ื ืขื“ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืฆื• ื–ื™ื™ึทืŸ ืคึผืจืึธื“ื•ืงื˜ืŸ (ืงืจื™ื˜ื™ืฉ ืคึผืึทื˜ืฉ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ), ืึทื™ืžืขื“ ืฆื• ืขืœื™ืžื™ื ื™ืจืŸ ืงืจื™ื˜ื™ืฉ ืคึผืจืึธื‘ืœืขืžืก ืื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. ืื™ืŸ ื“ื™ ืืคืจื™ืœ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื“ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ ืื™ืŸ ื’ืึทื ืฅ 297 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–.

ื™ืฉื•ื– Java SE 12.0.1, 11.0.3 ืื•ืŸ 8u212 5 ื–ื™ื›ืขืจื”ื™ื™ื˜ ื™ืฉื•ื– ืคืึทืจืคืขืกื˜ื™ืงื˜. ืึทืœืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ืจื™ืžืึธื•ื˜ืœื™ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ. ืื™ื™ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืกืคึผืขืฆื™ืคื™ืฉ ืฆื• ื“ื™ Windows ืคึผืœืึทื˜ืคืึธืจืžืข ืึทืกื™ื™ื ื“ CVSS Score 9.0 (CVE-2019-2699), ื•ื•ืึธืก ืงืึธืจืึทืกืคึผืึทื ื“ื– ืฆื• ืึท ืงืจื™ื˜ื™ืฉ ืžื“ืจื’ื” ืคื•ืŸ ื’ืขืคืึทืจ ืื•ืŸ ืึทืœืึทื•ื– ืึทืŸ ืึทื ืึธื˜ื”ืขื ื˜ื™ืงื™ื™ื˜ื™ื“ ื‘ืึทื ื™ืฆืขืจ ืื™ื‘ืขืจ ื“ื™ ื ืขืฅ ืฆื• ืงืึธืžืคึผืจืึธืžื™ืก Java SE ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–. ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ 2D ื’ืจืึทืคื™ืงืก ืคึผืจืึทืกืขืกื™ื ื’ ืกืึทื‘ืกื™ืกื˜ืึทื ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืึทืกื™ื™ื ื“ ืžื“ืจื’ื” 8.1 (CVE-2019-2697, CVE-2019-2698). ื“ืขื˜ืึทื™ืœืก ื–ืขื ืขืŸ ื ืึธืš ื ื™ืฉื˜ ื“ื™ืกืงืœืึธื•ื–ื“.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ื™ืฉื•ื– ืื™ืŸ Java SE, ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื’ืขืžืื›ื˜ ืขืคื ื˜ืœืขืš ืื™ืŸ ืื ื“ืขืจืข ืึธืจืึทืงืœืข ืคึผืจืึธื“ื•ืงื˜ืŸ, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜:

  • 40 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ MySQL (ืžืึทืงืกื™ืžื•ื ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ ืžื“ืจื’ื” 7.5). ื“ื™ ืžืขืจืกื˜ ื’ืขืคืขืจืœืขืš ืคึผืจืึธื‘ืœืขื
    (CVE-2019-2632) ืึทืคืขืงืฅ ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึผืœื•ื’ื™ืŸ ืกืึทื‘ืกื™ืกื˜ืึทื. ื™ืฉื•ื– ื•ื•ืขื˜ ื–ื™ื™ืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ืจื™ืœื™ืกื™ื– MySQL Community Server 8.0.16, 5.7.26 ืื•ืŸ 5.6.44.

  • 12 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ VirtualBox, ืคื•ืŸ ื•ื•ืึธืก 7 ื”ืึธื‘ืŸ ืึท ืงืจื™ื˜ื™ืฉ ื’ืจืึทื“ ืคื•ืŸ ื’ืขืคืึทืจ (CVSS ื›ืขื–ืฉื‘ืŸ 8.8). ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ VirtualBox 6.0.6 ืื•ืŸ 5.2.28 (ืื™ืŸ ื ืื˜ื™ืฅ ื“ืขืจ ืคืึทืงื˜ ืึทื– ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธื‘ืœืขืžืก ื–ืขื ืขืŸ ืกืึทืœื•ื•ื“ ืื™ื– ื ื™ืฉื˜ ืึทื“ื•ื•ืขืจื˜ื™ื™ื–ื“ ืื™ื™ื“ืขืจ ื“ื™ ืžืขืœื“ื•ื ื’). ื“ืขื˜ืึทื™ืœืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืฆื•ื’ืขืฉื˜ืขืœื˜, ืึธื‘ืขืจ ืื•ื™ื‘ ืžืฉืคื˜ืŸ ืœื•ื™ื˜ ื“ื™ ืžื“ืจื’ื” ืคื•ืŸ CVSS, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜, ื“ืขืžืึธื ืกื˜ืจื™ืจื˜ ืื™ืŸ ื“ื™ Pwn2Own 2019 ืคืึทืจืžืขืกื˜ ืื•ืŸ ืœืึธื–ืŸ ืื™ืจ ืฆื• ื•ื™ืกืคื™ืจืŸ ืงืึธื“ ืื•ื™ืฃ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืกื™ืกื˜ืขื ื–ื™ื™ึทื˜ ืคึฟื•ืŸ ื“ื™ ื’ืึทืกื˜ ืกื™ืกื˜ืขื ืกื•ื•ื™ื•ื•ืข.

    ืœืึธื–ืŸ ืื™ืจ ืฆื• ื‘ืึทืคืึทืœืŸ ื“ื™ ื‘ืึทืœืขื‘ืึธืก ืกื™ืกื˜ืขื ืคึฟื•ืŸ ื“ื™ ื’ืึทืกื˜ ืกื•ื•ื™ื•ื•ืข.

  • 3 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื•ื™ืฃ ืกืึธืœืึทืจื™ืก (ืžืึทืงืกื™ืžื•ื ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ 5.3 - ื™ืฉื•ื– ืžื™ื˜ IPS ืคึผืขืงืœ ืคืึทืจื•ื•ืึทืœื˜ืขืจ, SunSSH, ืื•ืŸ ืฉืœืึธืก ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’ ื“ื™ื ืกื˜. ื™ืฉื•ื– ืกืึทืœื•ื•ื“ ืื™ืŸ ืžืขืœื“ื•ื ื’
    Solaris 11.4 SRU8, ื•ื•ืึธืก ืื•ื™ืš ืจื™ื–ื•ืžื“ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ UCB ืœื™ื™ื‘ืจืขืจื™ื– (libucb, librpcsoc, libdbm, libtermcap, libcurses) ืื•ืŸ ื“ื™ fc-fabric ื“ื™ื ืกื˜, ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืคึผืขืงืœ ื•ื•ืขืจืกื™ืขืก
    ibus 1.5.19, NTP 4.2.8p12,
    Firefox 60.6.0esr,
    ื‘ื™ื ื“ืŸ 9.11.6
    OpenSSL 1.0.2r,
    MySQL 5.6.43 ืื•ืŸ 5.7.25,
    libxml2 2.9.9,
    libxslt 1.1.33,
    Wireshark 2.6.7,
    ncurses 6.1.0.20190105,
    ืึทืคึผืึทื˜ืฉื™ httpd 2.4.38,
    ืคึผืขืจืœ 5.22.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’